This URL gets the details of a light weight policy associated with a specific interface or sub interface.
Resource URL
GET /sensor/<sensor_id>/interface/<interface_id or subinterface_id>/localipspolicy
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| sensor_id | Sensor Id | Number | Yes |
| interface_id or subinterface_id | Unique interface or subinterface id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| PolicyDescriptor | Baseline IPS policy details | Object |
Details of PolicyDescriptor:
| Field Name | Description | Data Type |
|---|---|---|
| PolicyName | Baseline IPS policy name | String |
| Description | Policy description | String |
| IsVisibleToChildren | Is policy visible to child domain | Boolean |
| InboundRuleSet | Inbound policy rule set | String |
| OutboundRuleSet | Outbound policy rule set | String |
| AttackCategory | Attack category | Object |
| OutboundAttackCategory | Outbound attack category | Object |
| DosPolicy | DoS policy | Object |
| ReconPolicy | Recon policy | Object |
| DosResponseSensitivityLevel | DoS response sensitivity level | Number |
| IsEditable | Is policy editable | Boolean |
| Timestamp | Time stamp at which the policy was added | String |
| VersionNum | Policy version number | Number |
| IsLightWeightPolicy | Is light weight policy configured | Boolean |
Details of object in AttackCategory:
| Field Name | Description | Data Type |
|---|---|---|
| ExpolitAttackList | List of exploit attacks | Array |
Details of object in ExpolitAttackList:
| Field Name | Description | Data Type |
|---|---|---|
| attackName | Attack name | String |
| nspId | NSP id of the attack | String |
| severity | Attack severity, number between 0 & 9 | Number |
| isSeverityCustomized | Is attack severity customized | Boolean |
| isEnabled | Is attack enabled | Boolean |
| isAlertCustomized | Is alert customized | Boolean |
| isRecommendedForSmartBlocking | Is attack recommended for smart blocking | Boolean |
| AttackResponse | Attack response | Object |
| notification | Notifications configured | Object |
| protocolList | List of protocols | Array |
| applicationsImpactedList | List of applications impacted | Array |
| attackVector | List of attack vectors | Array |
| benignTriggerProbability | Attack benign trigger probability | String |
| target | Attack target, can be "Server" or "Client" | String |
| blockingType | Blocking type, can be "Attack Packet" | String |
| subCategory | Attack sub category | String |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| isAttackCustomized | Is attack customized | Boolean |
Details of object in AttackResponse:
| Field Name | Description | Data Type |
|---|---|---|
| TCPReset | TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH” | String |
| isTCPResetCustomized | Is TCP reset customized | Boolean |
| isICMPSend | Send ICMP host unreachable to source | Boolean |
| isICMPSendCustomized | Send ICMP host unreachable to source customized | Boolean |
| mcafeeNACNotification | NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS” | String |
| isMcafeeNACNotificationEnabled | Is NAC notification enabled | Boolean |
| isQuarantineCustomized | Is quarantine customized | Boolean |
| isRemediateEnabled | Is remediate enabled | Boolean |
| blockingOption | Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING” | String |
| isBlockingOptionCustomized | Is blocking option customized | Boolean |
| isCapturedPrior | Should application data be captured prior to attack | Boolean |
| isCapturedPriorCustomized | Should application data be captured prior to attack customized | Boolean |
| action | Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY” | String |
| isLogCustomized | Is logging customized | Boolean |
| flow | Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS” | String |
| isFlowCustomized | Customize flow type | Boolean |
| isNbytesCustomized | Is logging N bytes in each packet customized | Boolean |
| numberOfBytesInEachPacket | Number of bytes to be logged in each packet | Object |
| loggingDuration | Packet logging duration | Object |
| TimeStamp | Timestamp | String |
Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):
| Field Name | Description | Data Type |
|---|---|---|
| LogEntirePacket | Log entire packet | Object |
| CaptureNBytes | Capture N bytes | Object |
Details of object in CaptureNBytes:
| Field Name | Description | Data Type |
|---|---|---|
| NumberOfBytes | Number of bytes to log | Number |
Details of object in loggingDuration (Can be either of the below mentioned):
| Field Name | Description | Data Type |
|---|---|---|
| AttackPacketOnly | Log attack packet only | Object |
| CaptureNPackets | Capture N packets | Object |
| CaptureTimeDuration | Capture for a time duration | Object |
| RestOfFlow | Capture rest of flow | Object |
Details of object in CaptureNPackets:
| Field Name | Description | Data Type |
|---|---|---|
| npackets | Log n packets | number |
Details of object in CaptureTimeDuration:
| Field Name | Description | Data Type |
|---|---|---|
| time | Capture time | String |
| timeUnit | Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS" | String |
Details of object in notification:
| Field Name | Description | Data Type |
|---|---|---|
| isEmail | Is Notification configured through email | Boolean |
| isPager | Is Notification configured through pager | Boolean |
| isScript | Is Notification configured through script | Boolean |
| isAutoAck | Is Notification configured through auto ack | Boolean |
| isSnmp | Is Notification configured through SNMP | Boolean |
| isSyslog | Is Notification configured through Syslog | Boolean |
| isEmailCustomized | Is Notification through email customized | Boolean |
| isPagerCustomized | Is Notification through pager customized | Boolean |
| isScriptCustomized | Is Notification through script customized | Boolean |
| isAutoAckCustomized | Is Notification through auto ack customized | Boolean |
| isSnmpCustomized | Is Notification through SNMP customized | Boolean |
| isSyslogCustomized | Is Notification through Syslog customized | Boolean |
Details of object in DosPolicy:
| Field Name | Description | Data Type |
|---|---|---|
| LearningAttack | List of learning attacks | Array |
| ThresholdAttack | List of threshold attacks | Array |
| TimeStamp | Time stamp | String |
Details of object in LearningAttack:
| Field Name | Description | Data Type |
|---|---|---|
| attackName | Attack name | String |
| nspId | NSP id of the attack | String |
| isSeverityCustomized | Is attack severity customized | Boolean |
| severity | Attack severity, number between 0 & 9 | Number |
| isBlockingSettingCustomized | Is blocking customized | Boolean |
| isDropPacket | Drop DoS attack packets of this attack type when detected | Boolean |
| isAlertCustomized | Is alert customized | Boolean |
| isSendAlertToManager | Is alert notification to be sent to the Manager configured | String |
| timeStamp | Time stamp | String |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| notification | Notification to be sent via | Object |
| isAttackCustomized | Is DoS learning attack customized | Boolean |
Details of object in ThresholdAttack:
| Field Name | Description | Data Type |
|---|---|---|
| attackName | Attack name | String |
| nspId | NSP id of the attack | String |
| isSeverityCustomized | Is attack severity customized | Boolean |
| severity | Attack severity, number between 0 & 9 | Number |
| isThresholdValueCustomized | Is threshold value customized | Boolean |
| isThresholdDurationCustomized | is threshold duration customized | Boolean |
| ThresholdValue | Threshold values | Number |
| ThresholdDuration | Threshold Interval (Seconds) | Number |
| isAlertCustomized | Is alert customized | Boolean |
| isSendAlertToManager | Is alert notification to be sent to Manager configured | String |
| TimeStamp | Time stamp | String |
| Notification | Notification to be sent | Object |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| isAttackCustomized | Is DoS threshold attack customized | Boolean |
Details of object in ReconPolicy:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| ReconAttackList | List of recon attacks | Array | Yes |
| TimeStamp | Time stamp | String | Yes |
| attackName | Attack name | String | yes |
| nspId | NSP id of the attack | String | Yes |
| isSeverityCustomized | Is attack severity customized | Boolean | Yes |
| severity | Severity, number between 0 & 9 | Number | Yes |
| isThresholdValueCustomized | Is threshold value customized | Boolean | Yes |
| Is Threshold valuecustomized | is threshold duration customized | Boolean | Yes |
| ThresholdValue | Threshold values | Number | Yes |
| ThresholdDuration | Threshold Interval (seconds) | Number | Yes |
| mcAfeeNACNotification | Configured NAC notification that can be
"DISABLED" / "ALL_HOSTS" / "MCAFEE_NAC_UNMANAGED_HOSTS" |
String | Yes |
| isMcAfeeNACNotificationEnable | Is NAC notification enabled | Boolean | Yes |
| isQuarantineCustomized | Is quarantine customized | Boolean | Yes |
| isRemediateEnabled | is remediate enabled | Boolean | Yes |
| isAlertSuppressionTimerCustom | Is alert suppression customized | Boolean | Yes |
| alertSuppressionTimer | Alert suppression timer | Number | Yes |
| IsAlertCustomized | Is alert customized | Boolean | Yes |
| isSendAlertToManager | Is alert notification to be sent to Manager configured | String | Yes |
| timestamp | Time stamp | String | Yes |
| direction | Attack direction that can be "INBOUND" /
"OUTBOUND" / "BOTH" |
String | Yes |
| notification | Notification to be sent via | Object | Yes |
| isAttackCustomized | Is recon attack customized | Boolean | Yes |
Example
Request
GET https://%3CNSM_IP%3E/sdkapi/sensor/1001/interface/105/localipspolicy
Response
{
"PolicyDescriptor":
{
"PolicyName": "Local Policy - /My Company/M-2950/1A-1B clone",
"Description": "To test the policies",
"IsVisibleToChildren": true,
"InboundRuleSet": "testRuleSet",
"OutboundRuleSet": "Null",
"AttackCategory":
{
"ExpolitAttackList":
[
{
"attackName": "IDENT: TinyIdentD Identification Protocol Request Handling Remote Stack Overflow",
"nspId": "0x42700e00",
"severity": 6,
"isSeverityCustomized": true,
"isEnabled": true,
"isAlertCustomized": false,
"isRecommendedForSmartBlocking": false,
"AttackResponse":
{
"TCPReset": "DISABLED",
"isTcpResetCustomized": false,
"isICMPSend": false,
"isICMPSendCustomized": false,
"mcAfeeNACNotification": "DISABLED",
"isMcAfeeNACNotificationEnabled": false,
"isQuarantineCustomized": false,
"isRemediateEnabled": false,
"blockingOption": "DISABLE",
"isBlockingOptionCustomized": false,
"isCapturedPrior": true,
"isCapturedPriorCustomized": false,
"action": "SEND_ALERT_ONLY",
"isLogCustomized": false,
"isFlowCustomized": false,
"isNbytesCustomized": false,
"numberOfBytesInEachPacket":
{
"LogEntirePacket":
{
}
}
},
"notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"protocolList":
[
"ident"
],
"benignTriggerProbability": "3 (Medium)",
"blockingType": "attack-packet",
"subCategory": "buffer-overflow",
"direction": "INBOUND",
"isAttackCustomized": true
}
]
},
"OutboundAttackCategory":
{
},
"DosPolicy":
{
"LearningAttack":
[
{
"attackName": "Outbound ICMP Echo Request or Reply Volume Too High",
"nspId": "0x40018000",
"isSeverityCustomized": false,
"severity": 7,
"isBlockingSettingCustomized": false,
"isDropPacket": false,
"IsAlertCustomized": false,
"isSendAlertToManager": true,
"direction": "OUTBOUND",
"notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"isAttackCustomized": false
}
],
"ThresholdAttack":
[
{
"attackName": "Too Many Outbound IP Fragments",
"nspId": "0x40018800",
"isSeverityCustomized": false,
"severity": 6,
"isThresholdValueCustomized": false,
"isThresholdDurationCustomized": false,
"ThresholdValue": 1000,
"ThresholdDuration": 5,
"isAlertCustomized": false,
"isSendAlertToManager": false,
"Notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"direction": "OUTBOUND",
"isAttackCustomized": false
}
],
"TimeStamp": "2012-08-31 15:20:54.000"
},
'ReconPolicy': {
'TimeStamp': None,
'ReconAttackList': [{
'IsAlertCustomized': False,
'isSeverityCustomized': False,
'direction': None,
'severity': 5,
'isThresholdDurationCustomized': False,
'isSendAlertToManager': False,
'isQuarantineCustomized': False,
'attackName': 'BOTHeuristic: PotentialBotActivity-
MultipleResetsfromSMTPreceiver',
'ThresholdDuration': 0,
'alertSuppressionTimer': 0,
'isAlertSuppressionTimerCustomized': False,
'isAttackCustomized': False,
'isMcAfeeNACNotificationEnabled': False,
'isThresholdValueCustomized': False,
'nspId': '0x43f00900',
'mcAfeeNACNotification': 'DISABLED',
'isRemediateEnabled': False,
'timeStamp': None,
'ThresholdValue': 0,
'notification': {
'isSnmp': False,
'isAutoAckCustomized': False,
'isPagerCustomized': False,
'isSyslogCustomized': False,
'isEmail': False,
'isSyslog': False,
'isScriptCustomized': False,
'isSnmpCustomized': False,
'isScript': False,
'isPager': False,
'isEmailCustomized': False,
'isAutoAck': False
}
}]
},
"DosResponseSensitivityLevel": 0,
"IsEditable": false,
"Timestamp": "2012-08-31 15:20:55.000",
"VersionNum": 1,
"IsLightWeightPolicy": true
}
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | 1106 | Invalid Sensor |
| 2 | 404 | 1107 | Invalid interface or sub-interface id |
| 3 | 400 | 1301 | The number of attacks does not match the number in the baseline policy |
| 4 | 400 | 1302 | Number of bytes has to be between 1 to 255 |
| 5 | 400 | 1303 | Please provide the number of bytes to be logged |
| 6 | 400 | 1304 | Please provide duration of logging for flow |
| 7 | 400 | 1305 | Number of bytes has to be between 2 to 255 |
| 8 | 400 | 1306 | Time has to be between 1 to 63 |
| 9 | 400 | 1307 | Please provide a time |
| 10 | 400 | 1308 | Please provide a time interval |
| 11 | 400 | 1309 | Please provide the flow |
| 12 | 400 | 1310 | Invalid severity - please provide a value between 0 and 10 |
| 13 | 400 | 1311 | Invalid threshold value - please enter a value between 1 and 2147483647 |
| 14 | 400 | 1312 | Invalid threshold duration - please enter a value between 1 and 2147483647 |
| 15 | 400 | 1311 | Alert suppression timer should be between 1 and 65535 |